VulnerabilityModified
CVE-2021-3519
A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.
MEDIUM 6.8EPSS 0.24%
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- lenovo/ideacentre c5-14mb05 firmware · lenovo/ideacentre 3-07imb05 firmware · lenovo/ideacentre 5-14imb05 firmware · lenovo/ideacentre 5-14iob6 firmware · lenovo/ideacentre creator 5-14iob6 firmware · lenovo/ideacentre g5-14imb05 firmware · lenovo/ideacentre gaming 5-14iob6 firmware · lenovo/thinkcentre m60e tiny firmware · lenovo/thinkcentre m630e firmware · lenovo/thinkcentre m70a firmware · lenovo/thinkcentre m70s firmware · lenovo/thinkcentre m70t firmware · lenovo/thinkcentre m710e firmware · lenovo/thinkcentre m710s firmware · lenovo/thinkcentre m710t firmware · lenovo/thinkcentre m720e firmware · lenovo/thinkcentre m75n firmware · lenovo/thinkcentre m75s gen 2 firmware · lenovo/thinkcentre m70a gen 2 firmware · lenovo/thinkcentre m70c firmware · +39 more
- Source
- psirt@lenovo.com
References
- https://support.lenovo.com/us/en/product_security/LEN-67440Vendor Advisory
- https://support.lenovo.com/us/en/product_security/LEN-67440Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.